
Sign up to save your podcasts
Or

![Day[0]](https://podcast-api-images.s3.amazonaws.com/corona/show/870239/logo_300x300.jpeg)
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/a-flickr-csrf-gitlab-omigod-azure-again.html
Some high impact vulnerabilities this week, CSRF in account deletion, remote code execution as root, and an apache "0day" that discloses PHP source.
[00:00:23] [Flickr] CSRF in Account Deletion feature
[00:03:38] OMIGOD: Critical Vulnerabilities in OMI Affecting Countless Azure Customers
[00:23:38] How I found my first Adobe Experience Manager related bug.
[00:27:41] [GitLab] Stored XSS in main page of a project
[00:31:01] [Mattermost] Privilege Escalation leading to post in channel without having privilege
[00:34:15] Hacking CloudKit - How I accidentally deleted your Apple Shortcuts
[00:48:52] Apache 0day bug, which still nobody knows of, and which was fixed accidentally
The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:
The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/netgear-smart-switches-spookjs-parallels-desktop.html
This week we've got an awesome chain of attacks in NETGEAR smart switches, a speculative type confusion (Spook.js) and an integer overflow leading to HTTP Request Smuggling
[00:03:40] Security researchers fed up with Apple’s bug bounty program
[00:18:26] Demon's Cries vulnerability (some NETGEAR smart switches)
[00:22:21] Draconian Fear vulnerability (some NETGEAR smart switches)
[00:25:31] Seventh Inferno vulnerability (some NETGEAR smart switches)
[00:34:33] Spook.js - Speculative Type Confusion
[00:50:36] Critical vulnerability in HAProxy
[00:55:45] Ribbonsoft dxflib DL_Dxf::handleLWPolylineData Heap-Based Buffer Overflow Vulnerability
[01:03:43] Analysis of a Parallels Desktop Stack Clash Vulnerability and Variant Hunting using Binary Ninja
The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:
The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
Links and vulnerability summaries for this episode are available at: https://dayzerosec.com/podcast/reused-vmware-exploits-escaping-azure-container-instances.html
Some drama with the VMWare bounty program, and then a few straight forward vulnerabilities and a really cool Azure Container Instances escape and takeover.
[00:01:51] Exploit Fired At VMWare leaked to Nuclei Project.
[00:14:02] Bypassed! and uploaded a sweet reverse shell
[00:18:51] Local File Read via Stored XSS in The Opera Browser
[00:27:14] NETGEAR D7000 Authentication Bypass
[00:33:34] GitHub Actions check-spelling community workflow - GITHUB_TOKEN leakage via advice.txt symlink
[00:42:25] Create free Shopify application credits
[00:47:24] Cross-Account Container Takeover in Azure Container Instances
[00:58:59] IAM Vulnerable - An AWS IAM Privilege Escalation Playground
The DAY[0] Podcast episodes are streamed live on Twitch (@dayzerosec) twice a week:
The Video archive can be found on our Youtube channel: https://www.youtube.com/c/dayzerosec
You can also join our discord: https://discord.gg/daTxTK9
Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
A tricky to exploit WhatsApp vulnerability, but still an interesting bug, several Bhyve vulnerabilities, and a named bluetooth vuln (Braktooth)
Links and summaries are available on our website: https://dayzerosec.com/podcast/escaping-the-bhyve-whatsapp-braktooth.html
[00:00:00] Introduction + The Future
The DAY[0] Podcast has two weekly episodes that are streamed live on Twitch (https://www.twitch.tv/dayzerosec)
Mondays at 3pm Eastern we focus on vulnerabilities that would be of interest to bounty hunters, and on Tuesdays at 7:00pm Eastern we focus on low-level vulnerabilities.
You can also join our discord: https://discord.gg/daTxTK9 Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
Multiple account takeover vulnerabilities in this episode with three cross-origin communication vulnerabilities in Facebook, an odd OTP endpoint in SnapChat and an open redirect in JetBrains leaking your JWT.
Links and summaries are available on our website: https://dayzerosec.com/podcast/takeover-a-facebook-snapchat-or-jetbrains-account.html
[00:00:00] Introduction + The Future
The DAY[0] Podcast has two weekly episodes that are streamed live on Twitch (https://www.twitch.tv/dayzerosec)
Mondays at 3pm Eastern we focus on vulnerabilities that would be of interest to bounty hunters, and on Tuesdays at 7:00pm Eastern we focus on low-level vulnerabilities.
You can also join our discord: https://discord.gg/daTxTK9 Or follow us on Twitter (@dayzerosec) to know when new releases are coming.
Another short episode this week covering graphql attacks, a couple NoSQL injections, a few misconfigurations and a cool attack to reset monotonic counters on a Mifare card.
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
Or the video archive on Youtube (@dayzerosec)
A shorter episode, but some really cool vulns none-the-less, from mitigation bypassing on D-Link routers, to a new set of WiFi protocol design flaws.
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
Or the video archive on Youtube (@dayzerosec)
Kicking off the week with some awesome vulns, an "almost" padding oracle in Azure Functions, a race-condition in AWS Cognito, some sound engine bugs, and a Foxit Reader Use-after-free.
[00:00:52] Arbitrary Code Execution in the Universal Turing Machine [CVE-2021-32471]
[00:03:18] Detecting and annoying Burp users
[00:08:08] Enabling Hardware-enforced Stack Protection (cetcompat) in Chrome
[00:13:00] Password reset code brute-force vulnerability in AWS Cognito
[00:16:52] ASUS GT-AC2900 Authentication Bypass [CVE-2021-32030]
[00:20:10] The False Oracle - Azure Functions Padding Oracle Issue
[00:25:30] How I Hacked Google App Engine: Anatomy of a Java Bytecode Exploit
[00:38:01] Workplace by Facebook | Unauthorized access to companies environment
[00:42:39] Exploiting the Source Engine (Part 2) - Full-Chain Client RCE in Source using Frida
[00:53:11] [Valve] OOB reads in network message handlers leads to RCE
[01:01:07] Security probe of Qualcomm MSM data services
[01:05:17] Foxit Reader FileAttachment annotation use-after-free vulnerability
[01:09:45] Attack llvmpipe Graphics Driver from Chromium
[01:16:00] Privilege Escalation Via a Use After Free Vulnerability In win32k [CVE-2021-26900]
[01:26:25] 21Nails: Multiple vulnerabilities in Exim
[01:27:22] nRF52 Debug Resurrection (APPROTECT Bypass)
[01:28:56] Capture The Flag - Discussion Video
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
Or the video archive on Youtube (@dayzerosec)
Big episode this week, with a lot of discussion about CTFs, kernel drama, and Github's exploit policy. Then some really interesting exploit strategies on Tesla and Netgear, along with some simple, yet deadly issues in Wordpress and Composer.
Some drama in the Linux Kernel and so many vulns resulting in code execution in Homebrew, GitLab, an air fryer, Source engine, Super Mario Maker, Adobe Reader and the Linux Kernel.
[00:00:32] On the Feasibility of Stealthily Introducing Vulnerabilities in Open-Source Software via Hypocrite Commits
[00:15:18] Exploiting vulnerabilities in Cellebrite UFED and Physical Analyzer from an app's perspective
[00:22:30] [Ubuntu] OverlayFS LPE
[00:25:48] Synology DSM AppArmor synosearchagent misconfiguration
[00:28:22] [GitLab] RCE via unsafe inline Kramdown options
[00:35:25] [Homebrew] Broken parsing of Git diff allows an attacker to inject arbitrary Ruby scripts to Casks on official taps
[00:41:52] Remote code execution vulnerabilities in Cosori smart air fryer
[00:48:54] Source engine remote code execution via game invites [CVE-2021-30481]
[01:00:40] Discussion: Should programs be banned from Hackerone
[01:08:54] [Nintendo|3DS] Buffer Overflow in Super Mario Maker level decompression
[01:15:12] PrusaSlicer Obj.cpp load_obj() out-of-bounds write vulnerability
[01:20:12] Analysis of a use-after-free Vulnerability in Adobe Acrobat Reader DC
[01:31:21] Designing sockfuzzer, a network syscall fuzzer for XNU
[01:37:26] gaasedelen/tenet: A Trace Explorer for Reverse Engineers
[01:40:41] tmp.0ut
[01:44:35] Phœnix exploit / iOS 9.3.5
[01:46:02] Experiences with Apple Security Bounty
Watch the DAY[0] podcast live on Twitch (@dayzerosec) every Monday afternoon at 12:00pm PST (3:00pm EST)
Or the vide
From the publisher's feed

55 Listeners